CVE-2025-47615
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in flowdee Amazon Product in a Post amazon-product-in-a-post-plugin allows Stored XSS.This issue affects Amazon Product in a Post: from n/a through <= 5.2.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Stored XSS vulnerability in WordPress Amazon Product in a Post plugin up to v5.2.2 allows authenticated attackers to inject malicious scripts.
The vulnerability is a stored Cross-Site Scripting (XSS) flaw in the Amazon Product in a Post plugin for WordPress, affecting versions through 5.2.2. The root cause is improper neutralization of user-supplied input during web page generation, allowing malicious scripts to be stored in the database and later executed in the context of a victim's browser [1].
Exploitation requires an authenticated user with at least contributor-level privileges to inject crafted payloads via the plugin's input fields. The attacker does not need direct victim interaction to store the payload; however, according to the advisory, user interaction (such as the victim visiting a modified page) is necessary for the script to execute [1]. This distinction is typical for stored XSS, where the stored script triggers automatically upon page load.
The impact includes the ability to inject arbitrary HTML and JavaScript, leading to redirections, unwanted advertisements, or other malicious actions when guests visit compromised pages. Attackers could leverage this for session hijacking, phishing, or site defacement, potentially affecting thousands of sites due to mass-exploit campaigns targeting WordPress plugins [1].
As a mitigation, users should immediately update the Amazon Product in a Post plugin to the latest patched version beyond 5.2.2. The developer has not released a workaround, and no reliable alternative exists [1]. Given the active exploitation risk, site administrators are urged to prioritize this update.
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <=5.2.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.